Skip to content

[Aikido] Fix security issue in kotlin-stdlib via major version upgrade from 1.9.25 to 2.1.0 in agent - #341

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-18572-update-packages-89529418-bcbd
Closed

[Aikido] Fix security issue in kotlin-stdlib via major version upgrade from 1.9.25 to 2.1.0 in agent#341
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-18572-update-packages-89529418-bcbd

Conversation

@aikido-autofix

Copy link
Copy Markdown

Upgrade kotlin-stdlib to fix insecure temporary file permissions vulnerability allowing unauthorized data access and directory listing.

⚠️ Breaking changes analysis not available for: org.jetbrains.kotlin:kotlin-stdlib

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-550292
MEDIUM
[kotlin-stdlib] In JetBrains Kotlin, a vulnerable Java API is used for temporary file and folder creation. An attacker is able to read data from such files and list directories due to insecure permissions.
🔗 Related Tasks

@codecov

codecov Bot commented Aug 15, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #349

@aikido-autofix aikido-autofix Bot closed this Aug 23, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/AIK-18572-update-packages-89529418-bcbd branch August 23, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants